Saddleback Valley Unified School District
bd_4c987d129106b5c5 · schema v1 · pii pii-v1
Full breach record for Saddleback Valley Unified School District →Laguna Beach Unified School District (LBUSD) disclosed a data breach involving its Aeries Student Information System. An unauthorized individual exploited a vulnerability in the Aeries software in late November 2019, gaining access to student and parent data including names, addresses, emails, and hashed passwords. LBUSD confirmed the breach on May 14, 2020, after Aeries identified the exploit. Over 150 California school districts were impacted. LBUSD required password changes, installed a software patch, and disabled inactive accounts. Law enforcement investigated and identified the suspect.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_43b182a717b48fd9California State AGfiled 2020-06-24(26d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-190500
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 29, 2020
- Raw hash
- dfdf497970b1446f8e3978e204d5e3123d7f1e09a28d42193fae9f52ea28a470
Reporting entity
- Name
- Saddleback Valley Unified School Districtnorm: saddleback valley unified school district
Victim entity
- Name
- Saddleback Valley Unified School Districtnorm: saddleback valley unified school district
Incident
- Discovered
- May 14, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 15 days(15 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.